CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

160 vulnerabilities with CWE-354
CVE-2025-7096 HIGH
Comodo Internet Security Premium 12.3.4.8162 - Info Disclosure
CVSS 8.1
CVE-2025-39203 MEDIUM
MicroSCADA X SYS600 10.5-10.7 - Denial of Service via IEC 61850-8 Crafted Message
CVSS 6.5
CVE-2025-4418 MEDIUM
AVEVA PI Connector for CygNet <1.6.14 - Privilege Escalation
CVSS 4.4
CVE-2025-3479 MEDIUM
Forminator Forms - Custom Form Builder <1.42.0 - RCE
CVSS 5.3
CVE-2025-3247 MEDIUM
Contact Form 7 <6.0.5 - Order Replay
CVSS 5.3
CVE-2025-24148 MEDIUM
macOS <13.7.5-15.4-14.7.5 - Code Injection
CVSS 5.5
CVE-2025-25183 LOW
vllm < 0.7.2 - Cache Poisoning via Predictable Hash Collision
CVSS 2.6
CVE-2024-7402 HIGH
Netskope Client - Privilege Escalation
CVE-2024-46992 HIGH
Electron <30.0.5-31.0.0-beta.1 - ASAR Integrity Bypass
CVSS 7.8
CVE-2024-47573 MEDIUM
FortiNDR <7.4.2-7.0.6 - Privilege Escalation
CVSS 6.5
CVE-2024-47935 MEDIUM
TXOne Networks StellarProtect <3.2 - Privilege Escalation
CVSS 6.7
CVE-2024-56169 MEDIUM
nicmx fort_validator < 1.6.6 - Incomplete Route Origin Validation Data via Cache Fallback Failure
CVSS 5.3
CVE-2024-51141 HIGH
TOTOLINK Bluetooth Wireless Adapter A600UB - RCE
CVSS 7.8
CVE-2024-52550 HIGH
Jenkins Pipeline: Groovy Plugin <3990.vd281dd77a_388 - Improper Input Validation
CVSS 8.0
CVE-2024-49406 MEDIUM
Blockchain Keystore <1.3.16 - Privilege Escalation
CVSS 6.7
CVE-2024-47255 MEDIUM
2N Access Commander <3.1.1.2 - Privilege Escalation
CVSS 4.7
CVE-2024-49875 MEDIUM
Linux Kernel - Denial of Service via NFS EBADMSG Error Handling
CVSS 5.5
CVE-2024-48930 HIGH
secp256k1-node <5.0.1-3.8.1 - Info Disclosure
CVE-2024-47089 MEDIUM
Apex Softcell LD Geo - Privilege Escalation
CVSS 6.5
CVE-2024-45789 MEDIUM
Reedos aiM-Star 2.0.1 - Authenticated Registration Constraint Bypass via Mode Parameter
CVSS 4.3
CVE-2024-41909 MEDIUM
Apache MINA SSHD < 2.12.0 - Security Feature Downgrade via Terrapin Attack
CVSS 5.9
CVE-2024-3596 CRITICAL
FreeRADIUS < 3.0.27 - RADIUS Response Forgery via MD5 Chosen-Prefix Collision
CVSS 9.0
CVE-2024-31958 MEDIUM
Samsung Mobile Processor - Memory Corruption
CVSS 6.8
CVE-2024-34714 HIGH
hoppscotch-extension >= 0.28 < 0.35 - Improper Origin Validation
CVSS 7.6
CVE-2024-3727 HIGH
containers/image < 5.30.1 - Improper Validation of Integrity Check Value
CVSS 8.3
Details
Vulnerabilities 160
Exploit Likelihood Medium